unashamed/ai
All projects · Chrome extension
Chrome extension · Trade Me

Trade Me: Hide Promoted & Sponsored

Removes Sponsored / Promoted listings and Advertisements from Trade Me search results and category browsing, leaving only the organic listings. Works in both List and Gallery views.

Version1.0.0
Permissionsstorage only
Runs on*.trademe.co.nz, HTTPS, top frame
NetworkNone

How it works

Trade Me is an Angular app built from clean custom elements, so the signals are stable tag names rather than anything that needs de-obfuscating:

TargetSelectorAction
Sponsored / Promoted listingtm-sponsored-listings-taghide its tg-col grid cell
Promoted "super feature" card.tm-marketplace-search-card--super-featurehide its tg-col grid cell
Display adtm-display-ad-wrapper, tm-fuse-display-ad, tm-adsensehide its tg-col (or the ad)
Top banner adtm-shell-leaderboard-adhide the banner

Each listing lives in a tg-col grid cell, so hiding the whole cell lets the results grid reflow with no gaps. A MutationObserver re-applies the filter as you paginate, change filters or switch views.

Options (toolbar popup)

What it can touch

Manifest entryWhy it is there
permissions: ["storage"]Your popup settings, kept in chrome.storage.sync. That is the only permission requested.
host_permissionsNone. Not requested, not needed.
content_scripts.matches: ["https://*.trademe.co.nz/*"]HTTPS only, and only trademe.co.nz. No other site is touched.
content_scripts.all_frames: falseTop-level document only; nothing is injected into embedded iframes.
run_at: "document_start"So the page is filtered as it renders rather than flashing unfiltered first.
content_security_policyscript-src 'self': no remote code, no eval, no inline script.
Zero network requests, zero data sent anywhere. No analytics, no telemetry, no remote config, no remote script. The only network traffic is the site itself loading, exactly as it would without the extension. Your settings live in chrome.storage.sync (so they follow your Chrome profile) and nothing else is stored.

What it does not do

Honest caveats

Security

Follows the repo's shared security guidelines (the OWASP Browser Extension Vulnerabilities Cheat Sheet): storage is the only permission, the content script runs HTTPS-only in the top frame, a strict CSP forbids remote code, no innerHTML or eval, no network calls, and popup↔page messaging checks sender.id. A static audit (tests/owasp-audit.mjs) enforces all of that on every extension in the repo.

Install

  1. Download or clone the repo.
  2. Open chrome://extensions and turn on Developer mode (top right).
  3. Click Load unpacked and choose the chrome-extensions/trademe-remove-promoted-listings folder.
View the source and README →